Impact
A Linux kernel bug in the BPF subsystem allows a preemptible BPF program to trigger an out-of-bounds write while copying a per-CPU call‐chain buffer. The flaw occurs because the container holding the call‑chain entries can be reused between the demand of __bpf_get_stack and the copy. In a PREEMPT kernel, a non‑sleepable raw tracepoint program running under migrate_disable() but not preempt_disable() may be preempted after obtaining the buffer, allowing another task to reuse the same per‑CPU entry and inflate its length field. The copying code then uses this inflated length, causing a memcpy() to overflow the caller’s buffer and corrupt memory in the build_id resolution path. The required preemption guard was missing; the fix introduces preempt_disable() around the buffer acquisition and copy to ensure the entry cannot be reused, bounding trace->nr and preventing the overflow. This vulnerability represents an out‑of‑bounds write (CWE‑787). The affected vendors are Linux kernel maintainers; any kernel build that has not yet merged the commit disabling preemption around __bpf_get_stack is vulnerable. The flaw is local to the kernel; an attacker must be able to load a preemptible BPF program such as a raw tracepoint or other BPF program under migrate_disable() to trigger the overflow. It is therefore not a straightforward remote code execution but can lead to memory corruption, crashes, or privilege escalation if an attacker can raise privileges. The CVE is not listed in CISA KEV, and the EPSS score is <1%, indicating that active exploitation is unlikely. The CVSS score of 7.8 indicates a high severity, and the patch logic specifically disables preemption around the call‑chain buffer processing to eliminate the race between obtaining the entry and copying it.
Affected Systems
The vulnerability impacts all Linux kernel builds that contain the unpatched BPF implementation. The affected vendor No specific version information is supplied; any kernel version prior to the fix that includes the referenced commit is affected.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. EPSS score of <1%, and the vulnerability is not listed in CISA KEV, implying no publicly documented exploits. Exploitation requires local kernel or privileged access to inject BPF code, making remote exploitation unlikely under ordinary circumstances. Nonetheless, compromised nodes could experience memory corruption or a crash.
OpenCVE Enrichment
Debian DSA